VDB

CVE-2026-15154

CVE-2026-15154 PUBLISHED CVSS 6.5 MEDIUM

Reported by redhat · Published July 8, 2026

A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide specially crafted regular expressions to the public detection API. This can cause catastrophic backtracking, leading to a worker process consuming 100% CPU indefinitely and resulting in a denial of service for the entire guardrails-mediated LLM pipeline.

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
0
Red HatRed Hat OpenShift AI 2.251784230964
Red HatRed Hat OpenShift AI 2.251787235925
Red HatRed Hat OpenShift AI 3.31785137880
Red HatRed Hat OpenShift AI 3.41783569145
Red HatRed Hat OpenShift AI 3.41786617316
Red HatRed Hat OpenShift AI (RHOAI)
0, 0
Red HatRed Hat OpenShift AI 3.41786617316, 1783569145, 1783569145
Red HatRed Hat OpenShift AI 2.251787235925, 1784230964, 1784230964
Red HatRed Hat OpenShift AI 3.31785137880, 1785137880, 1785137880

Timeline

  • Jul 8, 2026 CVE Published
  • Jul 9, 2026 EPSS Score
  • Jul 9, 2026 Coalition ESS Score
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score
  • Aug 26, 2026 EPSS Score
  • Aug 28, 2026 EPSS Score
  • Aug 30, 2026 EPSS Score
  • Sep 3, 2026 EPSS Score
  • Sep 6, 2026 EPSS Score
  • Sep 8, 2026 CVE Updated
  • Sep 9, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›